7.2
CVE-2019-1649
- EPSS 0.23%
- Veröffentlicht 13.05.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:37:00
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based Secure Boot functionality. The vulnerability is due to an improper check on the area of code that manages on-premise updates to a Field Programmable Gate Array (FPGA) part of the Secure Boot hardware implementation. An attacker with elevated privileges and access to the underlying operating system that is running on the affected device could exploit this vulnerability by writing a modified firmware image to the FPGA. A successful exploit could either cause the device to become unusable (and require a hardware replacement) or allow tampering with the Secure Boot verification process, which under some circumstances may allow the attacker to install and boot a malicious software image. An attacker will need to fulfill all the following conditions to attempt to exploit this vulnerability: Have privileged administrative access to the device. Be able to access the underlying operating system running on the device; this can be achieved either by using a supported, documented mechanism or by exploiting another vulnerability that would provide an attacker with such access. Develop or have access to a platform-specific exploit. An attacker attempting to exploit this vulnerability across multiple affected platforms would need to research each one of those platforms and then develop a platform-specific exploit. Although the research process could be reused across different platforms, an exploit developed for a given hardware platform is unlikely to work on a different hardware platform.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Asa 5500 Firmware Version < 1.1.15
Cisco ≫ Asa 5506-x Version-
Cisco ≫ Asa 5506h-x Version-
Cisco ≫ Asa 5506w-x Version-
Cisco ≫ Asa 5508-x Version-
Cisco ≫ Asa 5516-x Version-
Cisco ≫ Asa 5506h-x Version-
Cisco ≫ Asa 5506w-x Version-
Cisco ≫ Asa 5508-x Version-
Cisco ≫ Asa 5516-x Version-
Cisco ≫ Firepower 2100 Firmware Version < 2.6.1.134
Cisco ≫ Firepower 2110 Version-
Cisco ≫ Firepower 2120 Version-
Cisco ≫ Firepower 2130 Version-
Cisco ≫ Firepower 2140 Version-
Cisco ≫ Firepower 2120 Version-
Cisco ≫ Firepower 2130 Version-
Cisco ≫ Firepower 2140 Version-
Cisco ≫ Firepower 4000 Firmware Version < 1.0.18
Cisco ≫ Firepower 4110 Version-
Cisco ≫ Firepower 4120 Version-
Cisco ≫ Firepower 4140 Version-
Cisco ≫ Firepower 4150 Version-
Cisco ≫ Firepower 4120 Version-
Cisco ≫ Firepower 4140 Version-
Cisco ≫ Firepower 4150 Version-
Cisco ≫ Firepower 9000 Firmware Version < 1.0.18
Cisco ≫ Ons 15454 Mstp Firmware Version < 11.1
Cisco ≫ Analog Voice Network Interface Modules Firmware HwPlatform4000_series_isrs
Cisco ≫ Nim-2bri-nt/te Version-
Cisco ≫ Nim-2fox Version-
Cisco ≫ Nim-2fxs Version-
Cisco ≫ Nim-2fxs/4fxo Version-
Cisco ≫ Nim-2fxs/4fxop Version-
Cisco ≫ Nim-2fxsp Version-
Cisco ≫ Nim-4bri-nt/te Version-
Cisco ≫ Nim-4e/m Version-
Cisco ≫ Nim-4fxo Version-
Cisco ≫ Nim-4fxs Version-
Cisco ≫ Nim-4fxsp Version-
Cisco ≫ Nim-2fox Version-
Cisco ≫ Nim-2fxs Version-
Cisco ≫ Nim-2fxs/4fxo Version-
Cisco ≫ Nim-2fxs/4fxop Version-
Cisco ≫ Nim-2fxsp Version-
Cisco ≫ Nim-4bri-nt/te Version-
Cisco ≫ Nim-4e/m Version-
Cisco ≫ Nim-4fxo Version-
Cisco ≫ Nim-4fxs Version-
Cisco ≫ Nim-4fxsp Version-
Cisco ≫ Integrated Services Router T1/e1 Voice And Wan Network Interface Modules Firmware HwPlatform4000_series
Cisco ≫ Nim-1ce1t1-pri Version-
Cisco ≫ Nim-1mft-t1/e1 Version-
Cisco ≫ Nim-2ce1t1-pri Version-
Cisco ≫ Nim-2mft-t1/e1 Version-
Cisco ≫ Nim-4mft-t1/e1 Version-
Cisco ≫ Nim-8ce1t1-pri Version-
Cisco ≫ Nim-8mft-t1/e1 Version-
Cisco ≫ Nim-1mft-t1/e1 Version-
Cisco ≫ Nim-2ce1t1-pri Version-
Cisco ≫ Nim-2mft-t1/e1 Version-
Cisco ≫ Nim-4mft-t1/e1 Version-
Cisco ≫ Nim-8ce1t1-pri Version-
Cisco ≫ Nim-8mft-t1/e1 Version-
Cisco ≫ Supervisor A+ Firmware HwPlatformnexus_9500
Cisco ≫ Supervisor B+ Firmware HwPlatformnexus_9500
Cisco ≫ 15454-m-wse-k9 Firmware Version < 11.1
Cisco ≫ Ios Xe Version < 16.3.9
Cisco ≫ Nim-1ge-cu-sfp Version-
Cisco ≫ Nim-2ge-cu-sfp Version-
Cisco ≫ Sm-x-pvdm-1000 Version-
Cisco ≫ Sm-x-pvdm-2000 Version-
Cisco ≫ Sm-x-pvdm-3000 Version-
Cisco ≫ Sm-x-pvdm-500 Version-
Cisco ≫ Nim-2ge-cu-sfp Version-
Cisco ≫ Sm-x-pvdm-1000 Version-
Cisco ≫ Sm-x-pvdm-2000 Version-
Cisco ≫ Sm-x-pvdm-3000 Version-
Cisco ≫ Sm-x-pvdm-500 Version-
Cisco ≫ Ios Xe Version >= 16.4.0 < 16.6.7
Cisco ≫ Nim-1ge-cu-sfp Version-
Cisco ≫ Nim-2ge-cu-sfp Version-
Cisco ≫ Sm-x-pvdm-1000 Version-
Cisco ≫ Sm-x-pvdm-2000 Version-
Cisco ≫ Sm-x-pvdm-3000 Version-
Cisco ≫ Sm-x-pvdm-500 Version-
Cisco ≫ Nim-2ge-cu-sfp Version-
Cisco ≫ Sm-x-pvdm-1000 Version-
Cisco ≫ Sm-x-pvdm-2000 Version-
Cisco ≫ Sm-x-pvdm-3000 Version-
Cisco ≫ Sm-x-pvdm-500 Version-
Cisco ≫ Ios Xe Version >= 16.7.0 < 16.9.4
Cisco ≫ Nim-1ge-cu-sfp Version-
Cisco ≫ Nim-2ge-cu-sfp Version-
Cisco ≫ Sm-x-pvdm-1000 Version-
Cisco ≫ Sm-x-pvdm-2000 Version-
Cisco ≫ Sm-x-pvdm-3000 Version-
Cisco ≫ Sm-x-pvdm-500 Version-
Cisco ≫ Nim-2ge-cu-sfp Version-
Cisco ≫ Sm-x-pvdm-1000 Version-
Cisco ≫ Sm-x-pvdm-2000 Version-
Cisco ≫ Sm-x-pvdm-3000 Version-
Cisco ≫ Sm-x-pvdm-500 Version-
Cisco ≫ Ios Xe Version >= 16.10.0 < 16.12.1
Cisco ≫ Nim-1ge-cu-sfp Version-
Cisco ≫ Nim-2ge-cu-sfp Version-
Cisco ≫ Sm-x-pvdm-1000 Version-
Cisco ≫ Sm-x-pvdm-2000 Version-
Cisco ≫ Sm-x-pvdm-3000 Version-
Cisco ≫ Sm-x-pvdm-500 Version-
Cisco ≫ Nim-2ge-cu-sfp Version-
Cisco ≫ Sm-x-pvdm-1000 Version-
Cisco ≫ Sm-x-pvdm-2000 Version-
Cisco ≫ Sm-x-pvdm-3000 Version-
Cisco ≫ Sm-x-pvdm-500 Version-
Cisco ≫ Industrial Security Appliances 3000 Firmware Version < 1.0.05
Cisco ≫ Integrated Services Router 4200 Firmware Version < 1.1
Cisco ≫ Integrated Services Router 4300 Firmware Version < 1.1
Cisco ≫ 4321 Integrated Services Router Version-
Cisco ≫ 4331 Integrated Services Router Version-
Cisco ≫ 4351 Integrated Services Router Version-
Cisco ≫ 4331 Integrated Services Router Version-
Cisco ≫ 4351 Integrated Services Router Version-
Cisco ≫ Integrated Services Router 4400 Firmware Version < 1.1
Cisco ≫ 4431 Integrated Services Router Version-
Cisco ≫ 44461 Integrated Services Router Version-
Cisco ≫ 4451-x Integrated Services Router Version-
Cisco ≫ 44461 Integrated Services Router Version-
Cisco ≫ 4451-x Integrated Services Router Version-
Cisco ≫ Ios Version < 15.6\(3\)m6b
Cisco ≫ 809 Industrial Integrated Services Routers Version-
Cisco ≫ 829 Industrial Integrated Services Routers Version-
Cisco ≫ 829 Industrial Integrated Services Routers Version-
Cisco ≫ Ios Version >= 15.7 <= 15.7\(3\)m4b
Cisco ≫ 809 Industrial Integrated Services Routers Version-
Cisco ≫ 829 Industrial Integrated Services Routers Version-
Cisco ≫ 829 Industrial Integrated Services Routers Version-
Cisco ≫ Ios Version >= 15.8 < 15.8\(3\)m2a
Cisco ≫ 809 Industrial Integrated Services Routers Version-
Cisco ≫ 829 Industrial Integrated Services Routers Version-
Cisco ≫ 829 Industrial Integrated Services Routers Version-
Cisco ≫ Asr 1000 Series Firmware
Cisco ≫ Asr 1000-esp100 Version-
Cisco ≫ Asr 1000 Series Version-
Cisco ≫ Asr1000-2t+20x1ge Version-
Cisco ≫ Asr1000-6tge Version-
Cisco ≫ Asr1000-esp200 Version-
Cisco ≫ Asr1000-mip100 Version-
Cisco ≫ Asr1000-rp3 Version-
Cisco ≫ Asr 1000 Series Version-
Cisco ≫ Asr1000-2t+20x1ge Version-
Cisco ≫ Asr1000-6tge Version-
Cisco ≫ Asr1000-esp200 Version-
Cisco ≫ Asr1000-mip100 Version-
Cisco ≫ Asr1000-rp3 Version-
Cisco ≫ Asr 1001 Firmware Version16.0.0
Cisco ≫ Ios Xe Version < 16.2.1
Cisco ≫ A900-rsp2a-128 Version-
Cisco ≫ A900-rsp2a-64 Version-
Cisco ≫ A900-rsp3c-200 Version-
Cisco ≫ A900-rsp3c-400/w Version-
Cisco ≫ Asr-920-10sz-pd Version-
Cisco ≫ Asr-920-12cz-a Version-
Cisco ≫ Asr-920-12cz-d Version-
Cisco ≫ Asr-920-12sz-a Version-
Cisco ≫ Asr-920-12sz-d Version-
Cisco ≫ Asr-920-12sz-im-cc Version-
Cisco ≫ Asr-920-24sz-m Version-
Cisco ≫ Asr-920-24tz-im Version-
Cisco ≫ Asr-920-24tz-m Version-
Cisco ≫ Asr-920-4sz-a Version-
Cisco ≫ Asr-920-4sz-d Version-
Cisco ≫ C9300-24p Version-
Cisco ≫ C9300-24t Version-
Cisco ≫ C9300-24u Version-
Cisco ≫ C9300-24ux Version-
Cisco ≫ C9300-48p Version-
Cisco ≫ C9300-48t Version-
Cisco ≫ C9300-48u Version-
Cisco ≫ C9300-48un Version-
Cisco ≫ C9300-48uxm Version-
Cisco ≫ Catalyst 9600 Supervisor Engine-1 Version-
Cisco ≫ Cbr-ccap-lc-40g-r Version-
Cisco ≫ Cbr-lc-8d31-16u31 Version-
Cisco ≫ A900-rsp2a-64 Version-
Cisco ≫ A900-rsp3c-200 Version-
Cisco ≫ A900-rsp3c-400/w Version-
Cisco ≫ Asr-920-10sz-pd Version-
Cisco ≫ Asr-920-12cz-a Version-
Cisco ≫ Asr-920-12cz-d Version-
Cisco ≫ Asr-920-12sz-a Version-
Cisco ≫ Asr-920-12sz-d Version-
Cisco ≫ Asr-920-12sz-im-cc Version-
Cisco ≫ Asr-920-24sz-m Version-
Cisco ≫ Asr-920-24tz-im Version-
Cisco ≫ Asr-920-24tz-m Version-
Cisco ≫ Asr-920-4sz-a Version-
Cisco ≫ Asr-920-4sz-d Version-
Cisco ≫ C9300-24p Version-
Cisco ≫ C9300-24t Version-
Cisco ≫ C9300-24u Version-
Cisco ≫ C9300-24ux Version-
Cisco ≫ C9300-48p Version-
Cisco ≫ C9300-48t Version-
Cisco ≫ C9300-48u Version-
Cisco ≫ C9300-48un Version-
Cisco ≫ C9300-48uxm Version-
Cisco ≫ Catalyst 9600 Supervisor Engine-1 Version-
Cisco ≫ Cbr-ccap-lc-40g-r Version-
Cisco ≫ Cbr-lc-8d31-16u31 Version-
Cisco ≫ Ios Xr Version7.0.1
Cisco ≫ A99-16x100ge-x-se Version-
Cisco ≫ A99-32x100ge-cm Version-
Cisco ≫ A99-32x100ge-tr Version-
Cisco ≫ A99-rp3-se Version-
Cisco ≫ A99-rp3-tr Version-
Cisco ≫ A9k-16x100ge-cm Version-
Cisco ≫ A9k-16x100ge-tr Version-
Cisco ≫ A9k-rsp5-se Version-
Cisco ≫ A9k-rsp5-tr Version-
Cisco ≫ Network Convergence System 1002 Version-
Cisco ≫ A99-32x100ge-cm Version-
Cisco ≫ A99-32x100ge-tr Version-
Cisco ≫ A99-rp3-se Version-
Cisco ≫ A99-rp3-tr Version-
Cisco ≫ A9k-16x100ge-cm Version-
Cisco ≫ A9k-16x100ge-tr Version-
Cisco ≫ A9k-rsp5-se Version-
Cisco ≫ A9k-rsp5-tr Version-
Cisco ≫ Network Convergence System 1002 Version-
Cisco ≫ Ios Xe Version < 15.5\(1\)sy4
Cisco ≫ C6800-16p10g-xl Version-
Cisco ≫ C6800-32p10g-xl Version-
Cisco ≫ C6800-8p10g-xl Version-
Cisco ≫ C6800-8p40g-xl Version-
Cisco ≫ C6800-sup6t-xl Version-
Cisco ≫ C6816-x-le Version-
Cisco ≫ C6824-x-le-40g Version-
Cisco ≫ C6832-x-le Version-
Cisco ≫ C6840-x-le-40g Version-
Cisco ≫ C6800-32p10g-xl Version-
Cisco ≫ C6800-8p10g-xl Version-
Cisco ≫ C6800-8p40g-xl Version-
Cisco ≫ C6800-sup6t-xl Version-
Cisco ≫ C6816-x-le Version-
Cisco ≫ C6824-x-le-40g Version-
Cisco ≫ C6832-x-le Version-
Cisco ≫ C6840-x-le-40g Version-
Cisco ≫ Ic3000-k9 Firmware Version < 1.0.2
Cisco ≫ Ncs2k-mr-mxp-k9 Firmware Version < 11.1
Cisco ≫ Ios Xr Version7.1.1
Cisco ≫ Nc55-24h12f-se Version-
Cisco ≫ Nc55-36x100g-a-se Version-
Cisco ≫ Nc55-36x100g-s Version-
Cisco ≫ Nc55-5504-fc Version-
Cisco ≫ Nc55-5516-fc Version-
Cisco ≫ Nc55-6x200-dwdm-s Version-
Cisco ≫ Nc55-mod-a-s Version-
Cisco ≫ Ncs-5501 Version-
Cisco ≫ Ncs-5501-se Version-
Cisco ≫ Ncs-5502 Version-
Cisco ≫ Ncs-5502-se Version-
Cisco ≫ Ncs-55a1-24h Version-
Cisco ≫ Ncs-55a1-36h-s Version-
Cisco ≫ Ncs-55a1-36h-se Version-
Cisco ≫ Ncs-55a2-mod-hd-s Version-
Cisco ≫ Ncs-55a2-mod-hx-s Version-
Cisco ≫ Ncs-55a2-mod-s Version-
Cisco ≫ Ncs-55a2-mod-se-h-s Version-
Cisco ≫ Ncs-55a2-mod-se-s Version-
Cisco ≫ Network Convergence System 5001 Version-
Cisco ≫ Network Convergence System 5002 Version-
Cisco ≫ Nc55-36x100g-a-se Version-
Cisco ≫ Nc55-36x100g-s Version-
Cisco ≫ Nc55-5504-fc Version-
Cisco ≫ Nc55-5516-fc Version-
Cisco ≫ Nc55-6x200-dwdm-s Version-
Cisco ≫ Nc55-mod-a-s Version-
Cisco ≫ Ncs-5501 Version-
Cisco ≫ Ncs-5501-se Version-
Cisco ≫ Ncs-5502 Version-
Cisco ≫ Ncs-5502-se Version-
Cisco ≫ Ncs-55a1-24h Version-
Cisco ≫ Ncs-55a1-36h-s Version-
Cisco ≫ Ncs-55a1-36h-se Version-
Cisco ≫ Ncs-55a2-mod-hd-s Version-
Cisco ≫ Ncs-55a2-mod-hx-s Version-
Cisco ≫ Ncs-55a2-mod-s Version-
Cisco ≫ Ncs-55a2-mod-se-h-s Version-
Cisco ≫ Ncs-55a2-mod-se-s Version-
Cisco ≫ Network Convergence System 5001 Version-
Cisco ≫ Network Convergence System 5002 Version-
Cisco ≫ Nx-os Version < 9.3\(2\)
Cisco ≫ N3k-c31108pc-v Version-
Cisco ≫ N3k-c31108tc-v Version-
Cisco ≫ N3k-c3132c-z Version-
Cisco ≫ N3k-c3264c-e Version-
Cisco ≫ N9k-c92300yc Version-
Cisco ≫ N9k-c93108tc-ex Version-
Cisco ≫ N9k-c93108tc-fx Version-
Cisco ≫ N9k-c93180lc-ex Version-
Cisco ≫ N9k-c93180yc-ex Version-
Cisco ≫ N9k-c93180yc-fx Version-
Cisco ≫ N9k-c93240yc-fx2 Version-
Cisco ≫ N9k-c9348gc-fxp Version-
Cisco ≫ N3k-c31108tc-v Version-
Cisco ≫ N3k-c3132c-z Version-
Cisco ≫ N3k-c3264c-e Version-
Cisco ≫ N9k-c92300yc Version-
Cisco ≫ N9k-c93108tc-ex Version-
Cisco ≫ N9k-c93108tc-fx Version-
Cisco ≫ N9k-c93180lc-ex Version-
Cisco ≫ N9k-c93180yc-ex Version-
Cisco ≫ N9k-c93180yc-fx Version-
Cisco ≫ N9k-c93240yc-fx2 Version-
Cisco ≫ N9k-c9348gc-fxp Version-
Cisco ≫ Nx-os Version < 8.4.1
Cisco ≫ Ds-x9648-1536k9 Version-
Cisco ≫ N3k-c3264c-e Version-
Cisco ≫ N77-m312cq-26l Version-
Cisco ≫ N77-m348xp-23l Version-
Cisco ≫ N77-sup3e Version-
Cisco ≫ N7k-m324fq-25l Version-
Cisco ≫ N7k-m348xp-25l Version-
Cisco ≫ N3k-c3264c-e Version-
Cisco ≫ N77-m312cq-26l Version-
Cisco ≫ N77-m348xp-23l Version-
Cisco ≫ N77-sup3e Version-
Cisco ≫ N7k-m324fq-25l Version-
Cisco ≫ N7k-m348xp-25l Version-
Cisco ≫ Sm-x-1t3/e3 Firmware Version-
Cisco ≫ Encs 5100 Firmware Version-
Cisco ≫ Encs 5400 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.23% | 0.464 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
psirt@cisco.com | 6.7 | 0.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-667 Improper Locking
The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.